Overview
A target system is a system in which Nova manages accounts and entitlements. Nova talks to target systems through connectors; it ships five:
- SAP – ABAP systems via RFC and BAPIs
- Active Directory and LDAP
- Microsoft Entra ID – via Microsoft Graph
- Keycloak – via the Admin API
- SCIM – applications with a SCIM 2.0 interface
Target systems of type “Miscellaneous” have no connector; Nova exchanges no data with them.
What Nova manages in target systems
All five connectors provide the same basic functions:
- Accounts: create them, change their master data, lock, unlock and delete them
- Passwords: set them
- Entitlements: grant and revoke them – roles in SAP, groups in all other target systems
- State: read an account's state – whether it exists, whether it is locked and, where the target system provides it, when it was last used
Nova takes over the catalogue of roles or groups as entitlements through an import job. Administrators define which master data of an identity goes into which attribute of the target system under “Administration” → “Provisioning” → “Mapping”.
| Target system | Entitlements | Locked via | Validity |
|---|---|---|---|
| SAP | single and composite roles | SAP user lock | in the target system |
| Active Directory | groups, including nested ones | userAccountControl | in Nova |
| LDAP | groups | password policy | in Nova |
| Entra ID | groups | accountEnabled | in Nova |
| Keycloak | groups | enabled | in Nova |
| SCIM | groups | active | in Nova |
Validity: only SAP understands validity periods of role assignments itself. Nova passes the start and end dates on, even when an assignment only begins in the future. The other target systems only know “member or not”. There, Nova holds back a future-dated assignment until its start date. A preconfigured job of type “Activate Pending Assignments” provisions such assignments of active identities daily at 02:30 (time zone Europe/Berlin).
Setting up a target system
Administrators create a target system under “Systems” → “Target Systems” → “Add target system”. Only administrators can create, change or delete target systems. A target system with a connector has:
- “Connection” – address and credentials, with rarely needed settings under “Advanced”. The pages of the individual connectors list the fields.
- “Account setup” – “Account ID template”, “Password ruleset” and “Account ID ruleset”. All three are mandatory; without them Nova does not save the target system. Administrators maintain the rulesets under “Administration” → “Provisioning” → “Password Rules” and “Account ID Rules”.
Account IDs
The “Account ID template” defines how Nova forms the ID of a new account, e.g. {first_initial_lower}{name_lower} → emustermann. Placeholders exist for first and last name, initial, full name, email address, personnel number and department; name parts are also available in lower or upper case. Nova removes accents and umlauts (Müller → Muller). An unknown placeholder causes an error rather than a wrong ID.
When a provisioning run creates an account, Nova forms the ID from the template and shortens it to the maximum length of the “Account ID ruleset”. If the ID is already taken in Nova or in the target system, Nova appends a number (emustermann2, emustermann3 … up to 99 at most). In future, Nova appends the number only when the ID is taken in Nova; if the target system holds an account with this ID that Nova does not know, Nova reports a conflict instead – see Accounts and passwords. planned
The “Account ID ruleset” limits the length and the permitted special characters, or prescribes a regular expression. Nova checks the ID against it when an account is created manually or linked. Nova ships a default ruleset for each connector, for example at most 12 characters for SAP.
The “Password ruleset” applies to passwords entered manually when an account is created or a password is set. Initial passwords that Nova generates itself are random, follow the ruleset and are at least 12 characters long.
Checking the connection
“Check status” in the list of target systems or in a target system's detail view tests the connection and stores the result – “online”, or “offline” with an error message. What is tested depends on the connector:
| Target system | Test |
|---|---|
| SAP | call of RFC_PING |
| Active Directory, LDAP | sign-in (bind) with the service account |
| Entra ID | retrieval of an access token |
| Keycloak | token retrieval and counting the accounts in the realm |
| SCIM | retrieval of ServiceProviderConfig, otherwise of the base URL |
A successful test proves reachability and sign-in, not every permission Nova will later need in the target system.
In addition, a preconfigured job of type “Target System Health Poll” checks the reachability of the target systems every ten minutes. When a system is newly found to be offline, Nova records this in the “Audit Log”.
Credentials
Nova stores passwords, client secrets and tokens of target systems encrypted in the database. The operator provides the key at start-up; it is not kept in the database. Nova returns stored secrets neither in the user interface nor through the programming interface; a placeholder is shown in their place. To change a secret, an administrator enters a new value. Secrets can neither be read nor set through the AI assistant.
Traceability
Nova records writes of the connectors in target systems in the change journal – with the values before and after.